ET MALWARE Cknife Shell Command Struct Inbound (PHP)

SID: 2022976Rev: 41 views
Sourceet/open
CreatedJuly 20, 2016
UpdatedMarch 12, 2024
Classificationtrojan-activity
alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET MALWARE Cknife Shell Command Struct Inbound (PHP)"; flow:established,to_server; http.method; content:"POST"; http.user_agent; content:"Java"; startswith; http.request_body; content:"=@eval"; fast_pattern; depth:9; content:"base64_decode"; distance:0; content:"&action="; distance:0; http.header_names; content:!"|0d 0a|Referer|0d 0a|"; content:"|0d 0a|User-Agent|0d 0a|"; startswith; reference:url,recordedfuture.com/web-shell-analysis-part-2; classtype:trojan-activity; sid:2022976; rev:4; metadata:attack_target Web_Server, created_at 2016_07_20, deployment Datacenter, performance_impact Low, signature_severity Major, updated_at 2024_03_12;)

Metadata

attack targetWeb_Server
created at2016_07_20
deploymentDatacenter
performance impactLow
signature severityMajor
updated at2024_03_12

Comments (0)

Please sign in to leave a comment.
Sign in

No comments yet. Be the first to comment!